appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers can l…
High CVSS 8.8
Summary
appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers can leverage authenticated access to generate a web shell with command execution capabilities by uploading a crafted PHP file to the site's uploads directory.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/apprain/apprain/archive/refs/tags/v4.0.5.zip Product
- https://www.apprain.org Product
- https://www.exploit-db.com/exploits/52041 Exploit
- https://www.vulncheck.com/advisories/apprain-cmf-authenticated-remote-code-execution-via-filemanager-upload Third Party Advisory
- https://github.com/apprain/apprain/archive/refs/tags/v4.0.5.zip Product
Timeline
- nvd_ingest NVD